There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
History

Thu, 15 Jan 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Hikvision
Hikvision ds-2cd1xx1
Hikvision ds-2cd1xxxg0(t)
Hikvision ds-2cd1xxxg2
Hikvision ds-2cd29xxg0
Hikvision ds-2cd2dx5g1
Hikvision ds-2cd2xx1g0
Hikvision ds-2cd3xx1g0
Hikvision ds-2cd3xx1g2
Hikvision ds-2cd64x5g1
Hikvision ds-2xc6xxxg0
Hikvision ds-2xe6xxxg0
Hikvision ds-710xni-g1/(xp)/m
Hikvision ds-71xxhghi-m1(/t)
Hikvision ds-71xxni-q1(/xp)
Hikvision ds-71xxni-q1(/xp)/m
Hikvision ds-72xxhghi-m1(/t)
Hikvision ds-76xxni-mx
Hikvision ds-76xxni-q1(/xp)
Hikvision ds-76xxni-q2(/xp)
Hikvision ds-76xxni-qx(/xp)
Hikvision ds-76xxnxi-ix/s
Hikvision ds-76xxnxi-ix/vpro
Hikvision ds-76xxnxi-k1(/xp)
Hikvision ds-76xxnxi-k1(/xp)/vpro
Hikvision ds-76xxnxi-k2(/xp)
Hikvision ds-76xxnxi-k2(/xp)/vpro
Hikvision ds-76xxnxi-kx(/xp)
Hikvision ds-76xxnxi-kx(/xp)/vpro
Hikvision ds-76xxnxi-mx/vpro
Hikvision ds-77xxni-mx
Hikvision ds-77xxnxi-ix/s
Hikvision ds-77xxnxi-ix/vpro
Hikvision ds-77xxnxi-k4(/xp)
Hikvision ds-77xxnxi-k4(/xp)/vpro
Hikvision ds-77xxnxi-kx(/xp)
Hikvision ds-77xxnxi-kx(/xp)/vpro
Hikvision ds-86xxnxi-ix/s
Hikvision ds-86xxnxi-k8(/xp)
Hikvision ds-86xxxnxi-mx
Hikvision ds-96xxnxi-ix/s
Hikvision ds-96xxnxi-mx
Hikvision ds-96xxnxi-mx/vpro
Hikvision ds-96xxnxi-sx
Hikvision ds-96xxxni-hx
Hikvision ds-96xxxni-ix
Hikvision ds-96xxxnxi-mx
Hikvision ds-96xxxnxi-sx
Hikvision ds-a806xxsi
Hikvision ds-at1000si
Hikvision ds-exxhghi-xx
Hikvision hwi-xxxh(c)
Hikvision hwi-xxxxha
Hikvision ids-6704nxi/ai
Hikvision ids-67xxnxi-mx/ai
Hikvision ids-67xxnxi-mx/x
Hikvision ids-67xxnxi-p1
Hikvision ids-67xxnxi-s
Hikvision ids-67xxnxi-s/t
Hikvision ids-67xxxnxi-mx/ai
Hikvision ids-71xxhghi-m1(/t)
Hikvision ids-71xxhqhi-m1(/t)
Hikvision ids-71xxhqhi-m1/s
Hikvision ids-71xxhqhi-m1/t
Hikvision ids-71xxhuhi-m1/s
Hikvision ids-72xxhghi-m1(/t)
Hikvision ids-72xxhqhi-m1(/t)
Hikvision ids-72xxhqhi-m1/e
Hikvision ids-72xxhqhi-m1/t
Hikvision ids-72xxhqhi-mx/xt
Hikvision ids-72xxhthi-mx/xt
Hikvision ids-72xxhuhi-m1/e
Hikvision ids-72xxhuhi-m1/t
Hikvision ids-72xxhuhi-mx/pxt
Hikvision ids-72xxhuhi-mx/x
Hikvision ids-72xxhuhi-mx/xt
Hikvision ids-73xxhqhi-m4/s
Hikvision ids-73xxhuhi-m4/s
Hikvision ids-73xxhuhi-m4/s(s)
Hikvision ids-7608nxi-p2
Hikvision ids-76xxnxi-mx/x
Hikvision ids-77xxnxi-mx/x
Hikvision ids-77xxnxi-p4
Hikvision ids-81xxhqhi-m8/s
Hikvision ids-81xxhuhi-m8/s(s)
Hikvision ids-90xxhqhi-m8/s
Hikvision ids-90xxhuhi-m8/s
Hikvision ids-90xxhuhi-m8/s(s)
Hikvision ids-96064nxi-i16
Hikvision ids-96xxnxi-mx/ai
Hikvision ids-96xxnxi-mx/x
Hikvision ids-96xxnxi-px
Hikvision ids-96xxxnxi-hx
Hikvision ids-96xxxnxi-hx/ai
Hikvision ids-96xxxnxi-ix/ai
Hikvision ids-96xxxnxi-mx/x
Hikvision ids-exxhqhi-xx
Hikvision ids-exxhuhi-xx
Hikvision ipc-xxxxh
Hikvision ipc-xxxxha
Vendors & Products Hikvision
Hikvision ds-2cd1xx1
Hikvision ds-2cd1xxxg0(t)
Hikvision ds-2cd1xxxg2
Hikvision ds-2cd29xxg0
Hikvision ds-2cd2dx5g1
Hikvision ds-2cd2xx1g0
Hikvision ds-2cd3xx1g0
Hikvision ds-2cd3xx1g2
Hikvision ds-2cd64x5g1
Hikvision ds-2xc6xxxg0
Hikvision ds-2xe6xxxg0
Hikvision ds-710xni-g1/(xp)/m
Hikvision ds-71xxhghi-m1(/t)
Hikvision ds-71xxni-q1(/xp)
Hikvision ds-71xxni-q1(/xp)/m
Hikvision ds-72xxhghi-m1(/t)
Hikvision ds-76xxni-mx
Hikvision ds-76xxni-q1(/xp)
Hikvision ds-76xxni-q2(/xp)
Hikvision ds-76xxni-qx(/xp)
Hikvision ds-76xxnxi-ix/s
Hikvision ds-76xxnxi-ix/vpro
Hikvision ds-76xxnxi-k1(/xp)
Hikvision ds-76xxnxi-k1(/xp)/vpro
Hikvision ds-76xxnxi-k2(/xp)
Hikvision ds-76xxnxi-k2(/xp)/vpro
Hikvision ds-76xxnxi-kx(/xp)
Hikvision ds-76xxnxi-kx(/xp)/vpro
Hikvision ds-76xxnxi-mx/vpro
Hikvision ds-77xxni-mx
Hikvision ds-77xxnxi-ix/s
Hikvision ds-77xxnxi-ix/vpro
Hikvision ds-77xxnxi-k4(/xp)
Hikvision ds-77xxnxi-k4(/xp)/vpro
Hikvision ds-77xxnxi-kx(/xp)
Hikvision ds-77xxnxi-kx(/xp)/vpro
Hikvision ds-86xxnxi-ix/s
Hikvision ds-86xxnxi-k8(/xp)
Hikvision ds-86xxxnxi-mx
Hikvision ds-96xxnxi-ix/s
Hikvision ds-96xxnxi-mx
Hikvision ds-96xxnxi-mx/vpro
Hikvision ds-96xxnxi-sx
Hikvision ds-96xxxni-hx
Hikvision ds-96xxxni-ix
Hikvision ds-96xxxnxi-mx
Hikvision ds-96xxxnxi-sx
Hikvision ds-a806xxsi
Hikvision ds-at1000si
Hikvision ds-exxhghi-xx
Hikvision hwi-xxxh(c)
Hikvision hwi-xxxxha
Hikvision ids-6704nxi/ai
Hikvision ids-67xxnxi-mx/ai
Hikvision ids-67xxnxi-mx/x
Hikvision ids-67xxnxi-p1
Hikvision ids-67xxnxi-s
Hikvision ids-67xxnxi-s/t
Hikvision ids-67xxxnxi-mx/ai
Hikvision ids-71xxhghi-m1(/t)
Hikvision ids-71xxhqhi-m1(/t)
Hikvision ids-71xxhqhi-m1/s
Hikvision ids-71xxhqhi-m1/t
Hikvision ids-71xxhuhi-m1/s
Hikvision ids-72xxhghi-m1(/t)
Hikvision ids-72xxhqhi-m1(/t)
Hikvision ids-72xxhqhi-m1/e
Hikvision ids-72xxhqhi-m1/t
Hikvision ids-72xxhqhi-mx/xt
Hikvision ids-72xxhthi-mx/xt
Hikvision ids-72xxhuhi-m1/e
Hikvision ids-72xxhuhi-m1/t
Hikvision ids-72xxhuhi-mx/pxt
Hikvision ids-72xxhuhi-mx/x
Hikvision ids-72xxhuhi-mx/xt
Hikvision ids-73xxhqhi-m4/s
Hikvision ids-73xxhuhi-m4/s
Hikvision ids-73xxhuhi-m4/s(s)
Hikvision ids-7608nxi-p2
Hikvision ids-76xxnxi-mx/x
Hikvision ids-77xxnxi-mx/x
Hikvision ids-77xxnxi-p4
Hikvision ids-81xxhqhi-m8/s
Hikvision ids-81xxhuhi-m8/s(s)
Hikvision ids-90xxhqhi-m8/s
Hikvision ids-90xxhuhi-m8/s
Hikvision ids-90xxhuhi-m8/s(s)
Hikvision ids-96064nxi-i16
Hikvision ids-96xxnxi-mx/ai
Hikvision ids-96xxnxi-mx/x
Hikvision ids-96xxnxi-px
Hikvision ids-96xxxnxi-hx
Hikvision ids-96xxxnxi-hx/ai
Hikvision ids-96xxxnxi-ix/ai
Hikvision ids-96xxxnxi-mx/x
Hikvision ids-exxhqhi-xx
Hikvision ids-exxhuhi-xx
Hikvision ipc-xxxxh
Hikvision ipc-xxxxha

Tue, 13 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121

Tue, 13 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 02:30:00 +0000

Type Values Removed Values Added
Description There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hikvision

Published: 2026-01-13T01:47:54.031Z

Updated: 2026-01-13T17:27:13.199Z

Reserved: 2025-11-24T08:59:35.903Z

Link: CVE-2025-66177

cve-icon Vulnrichment

Updated: 2026-01-13T14:26:11.902Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T03:16:01.250

Modified: 2026-01-13T18:16:06.193

Link: CVE-2025-66177

cve-icon Redhat

No data.